Skip to content
Identity Sourcing

From systems of record to Day-1-ready accounts

Aquera Identity Sourcing connects every system of record, HCM, candidate recruiting, contract and contingent worker sources, and B2B partner users, to your directories. Records are correlated, transformed, and synchronized into Active Directory and cloud-only users, then flow onward to Microsoft 365. No scripting, no manual tickets.

Trusted by 1,500+ Organizations Worldwide

Wingstop_logo Warby_Parker_logo Lucid_Motors_logo JD_Sports_logo Silicon_Valley_Bank_logo_(2018) Allbirds_logo Allergan_logo backblaze_92n7 Forbes_logo Aptiv_logo Casper_Sleep_logo.svg Opendoorlogo.svg squarespace-logo-horizontal-black IonQ_corp_logo.svg Lindt-Logo images FIGS_Inc_Logo E.l.f.-Logo everlane-logo-vector images (1) 656661c5e4f9dbb18f4bd724_Matterport Myfitnesspal-Logo-Vector.svg- StoneX_Group_Inc_official_2023_logo.svg kisspng-keller-williams-realty-lake-charles-clarks-summit-5b08ba53863a91.8378231615272986435498 Bupa_logo.svg wwf_logo_large_rgb_72dpi_1_1_1_1_783732 b5586b9a-1c73-46ad-bccf-09ab444e2def-1
What It Delivers

Your systems of record decide who. Aquera delivers the accounts

Every hire, transfer, and termination becomes the right accounts, group memberships, and licenses, on Day 1, in the user's local time zone.

Day 1
readiness through early onboarding from pre-hire records
Local time
on/offboarding at the user’s correct local time, in every zone
No queueing
fault-resilient incremental sync with no store and forward
The Gap

Solving the sourcing gap

Where sourcing breaks
Many sources. Employees, candidates, contractors, partners, and non-employees each arrive from a different system of record.
Manual matching. Directory records without a unique identifier get matched by hand, or never, leaving duplicates and orphans.
Wrong timing. Accounts appear after start dates and linger after terminations, triggered in the admin’s time zone, not the user’s.
How Aquera closes it
One-to-one matching. AI and ML matching links each system-of-record entry to one and only one directory record, writing the employee number back.
Generated maps. Generated transformation maps convert source attributes into target directory fields, across multiple targets.
Early, local-time onboarding. Early onboarding plus future-dated scheduling, for example provisioning 3 days before the hire date at 9:00 am local time.
Fail-safe controls. Fail-safe controls with transaction approval rules guard every change before it reaches your directories.
Go Deeper

Identity Sourcing datasheet

Correlation, transformation maps, username generation, group membership rules, Microsoft 365 automation, and the full deployment flow.

Download the datasheet
Core Product Capabilities

HR-driven identity sourcing, with audit-grade operational control

Correlate & Link

AI and ML algorithms with a review workbench match each record to one directory account, fuzzy-matching the rest and excluding service accounts.

Transformation Maps

Source attributes with transform logic mapped to target fields, uppercasing, concatenation, and lookups, generated then reviewed and refined.

Username Generation

Pattern-based unique usernames checked against Active Directory, Okta, Entra ID, and databases before writing UPN, email, and samAccountName.

Group Membership

Analyze in-scope groups, generate candidate rules from attributes such as department and cost center, and automate adds and removals.

When Identities Come From Multiple Sources

One resolved identity per person, with Master Identity Index

The same person can arrive from several systems of record: a contractor who converts to employee, a rehire, a partner user with an HCM record. Sourcing each feed independently creates duplicates.

With multiple systems of record feeding Identity Sourcing, Aquera Master Identity Index correlates identities across every source, links them into one durable record per entity, and assigns a single persistent anchor ID that is stamped into every connected system. Correlation becomes a deterministic, upstream fact that every directory account inherits. Records survive departure, so returners re-match to their existing identity instead of being recreated as orphans.

How they work together: Systems of record feed MII → MII resolves each person to one anchor ID → Identity Sourcing provisions and synchronizes the resolved identity into your directories.

Cross-Source Correlation

Resolve and link identities across HR, ATS, contractor, partner, and volunteer systems into one record per entity, human and non-human.

Persistent Anchor ID

One durable anchor ID per identity, written to stable attributes, so accounts stay correlated across renames, moves, rehires, and tenure gaps.

Link & Unlink History

Merge records that are the same person; split bad matches without losing history. Audits see what was linked, when, and why.

Inside Identity Sourcing

Everything that has to be right for Day 1 to actually work

Early Onboarding

To-be-hired and pre-hire records create accounts early for validation, with joiner tickets raised in your ITSM for Day-1 readiness.

Time-Zone Aware Actions

Actions trigger on the user’s local time, not the admin’s, with configurable offsets and future-dated scheduling.

Full Microsoft 365 Automation

Licenses, distribution lists, shared mailboxes, and OneDrive on join; mailbox conversion, session revocation, and device cleanup on exit.

Incremental Sync

Fault-resilient polling with no store and forward. Aquera tracks queue position and advances only on success, over TLS-encrypted transfers.

Fail-Safe Controls

Transaction approval rules, thresholds, and exception handling with recommendations protect directories from runaway changes.

Operations Center

Transaction analysis and approvals, forensics search, savings analysis, and unified logging, every action audited.

Deployment

Generated configuration, not a custom integration project

1 ANALYZE

Integration analysis

Aquera analyzes record linking, attribute transformation, and group membership using AI and ML algorithms with a review workbench.

2 GENERATE

Generated configuration

Linked systems of record, transformation maps, group assignment rules, username patterns, and reference lookups, generated rather than hand-coded.

3 OPERATE

Operational configuration

Schedules, notifications, fail-safes, time-of-day on/offboarding, attribute writebacks, and shared resource cleanup at offboarding.

Let's Talk

See Identity Sourcing in Action

A 30-minute working session mapped to your systems of record, scoped to what you actually run.

Request a Demo

Frequently asked questions

What is Aquera Identity Sourcing? +

Aquera Identity Sourcing is an HR-driven identity automation engine that connects every system of record, HCM, candidate recruiting (ATS), contract and contingent worker systems of record, B2B partner user systems of record, and non-employee identity management, to your directories. Records are correlated, transformed, and synchronized into Active Directory users and cloud-only users in Okta or Entra ID, then flow onward to Microsoft 365, with no scripting and no manual tickets.

What problem does Aquera Identity Sourcing solve? +

Identity lives in many places: employees, candidates, contractors, partners, and non-employees each arrive from a different system of record, directory records without a unique identifier get matched by hand, and accounts appear after start dates or linger after terminations. Identity Sourcing automates correlation, attribute transformation, unique username generation, group membership, and on/offboarding timing so every hire, transfer, and termination produces the right accounts, group memberships, and licenses on Day 1, in the user’s local time zone.

How does Aquera Identity Sourcing work? +

Systems of record feed Aquera’s identity sourcing automation, which correlates, transforms, and syncs each record into your directories. Accounts are created as Active Directory users and/or cloud-only users, with AD accounts synchronized onward to Entra ID or Okta and Microsoft 365. The result is Day-1 readiness through early onboarding, on/offboarding at the user’s correct local time, and fault-resilient incremental sync with no store and forward.

What are the core capabilities of Aquera Identity Sourcing? +

Four core capabilities: Correlate and Link, Transformation Maps, Username Generation, and Group Membership, backed by incremental sync, fail-safe controls, and the Aquera Operations Center.

Which systems of record does Aquera Identity Sourcing support? +

HCM platforms, candidate recruiting (ATS) systems, contract and contingent worker systems of record, B2B partner user systems of record, and non-employee identity management systems, all feeding one sourcing engine.

Which directories and identity platforms does it provision? +

Aquera Identity Sourcing provisions Active Directory users and cloud-only users in Okta or Entra ID, and synchronized identities flow onward from Active Directory to Entra ID or Okta and Microsoft 365, covering office workers in AD and frontline, cloud-only users.

Can Aquera provision cloud-only users for frontline workers? +

Yes. Frontline workers are provisioned as cloud-only users in Okta or Entra ID, while office workers receive Active Directory accounts, and AD users receive group, attribute, and Microsoft 365 offboarding updates.

How does Aquera correlate HR records with existing directory accounts? +

AI and ML matching algorithms with a review workbench link each system-of-record entry to one and only one directory record. Aquera first matches on unique identifiers such as employee number, fuzzy-matches the remainder on attributes like name and email, writes the employee number back into matched records, and excludes out-of-scope records such as service accounts.

How do attribute transformation maps work? +

Aquera generates an attribute transformation map for each target: source HCM fields with transform logic, uppercasing, concatenation, and reference lookups, mapped to target directory fields across multiple targets. Generated mappings are then reviewed, modified, or excluded as required.

How does Aquera generate unique usernames? +

From preferred patterns, comparing each candidate against reference user stores including Active Directory domains, Okta, Entra ID, and databases, before writing the unique value to fields such as User Principal Name, email address, samAccountName, and Common Name.

How does Aquera automate directory group membership? +

Aquera analyzes in-scope directory groups, generates candidate membership rules from user attributes such as department, branch, and cost center, and automates group adds and removals, driving downstream application assignments from directory group membership.

How does Aquera ensure new hires are ready on Day 1? +

Early onboarding: to-be-hired candidates from the ATS recruiting module and pre-hire status employees from core HR create accounts early for validation or review, generate joiner tickets in IT Service Management, and initiate any manual processes, so access is ready on Day 1.

Does Aquera support time-zone aware onboarding and offboarding? +

Yes. Account creation, notification, and deactivation trigger at the user’s correct local time in every office, not the admin’s time zone, with configurable HCM-aligned offsets and future-dated scheduling. Actions can run a set number of days before or after the hire or termination date.

What happens when identities come from multiple sources? +

The same person can arrive from several systems of record, a contractor who converts to employee, a rehire, or a partner user with an HCM record, and sourcing each feed independently creates duplicates. With multiple sources feeding Identity Sourcing, Aquera Master Identity Index correlates identities across every source, links them into one durable record per entity, and assigns a single persistent anchor ID stamped into every connected system.

How do Identity Sourcing and Master Identity Index work together? +

Systems of record feed Master Identity Index; MII resolves each person to one anchor ID; Identity Sourcing provisions and synchronizes the resolved identity into your directories. Correlation becomes a deterministic, upstream fact that every directory account inherits, and records survive departure so returners re-match to their existing identity instead of being recreated as orphans.

What does Aquera automate in Microsoft 365? +

On join: creating cloud-only users, updating existing users, assigning group memberships and Microsoft 365 licenses, and creating distribution lists, shared mailboxes, and shared OneDrive locations. On exit: mailbox conversion to shared with auto-reply and manager forwarding, session revocation, removal of group memberships, app roles and delegations, device cleanup including Intune-managed devices, manager access to OneDrive, license reclaim with reassignment logic, and litigation hold support.

How does Aquera keep directories in sync with HR systems? +

Incremental sync polls the system of record for changes using a last-modified queue, retrieves the full changed record by ID, and synchronizes directory attributes and group assignments, tracking its position in the queue and advancing only when an update succeeds.

Is Aquera Identity Sourcing fault tolerant? +

Yes. A fault-resilient architecture with no store and forward: data is not queued in intermediate storage, transfers are TLS encrypted, notifications report sync activity, and the engine updates its queue position only when a change is applied successfully.

What fail-safe controls does it provide? +

Fail-safe controls with transaction approval rules and thresholds, plus exception handling with recommendations and actions, protecting directories from runaway or unintended changes before they are applied.

How is Aquera Identity Sourcing deployed? +

Deployment starts with integration analysis, then generates the configuration: linked systems of record, transformation maps across multiple targets, group assignment rules, unique username generation, and reference data lookup tables. Operational configuration follows: schedules, notifications, fail-safe controls, time-of-day on/offboarding, attribute writebacks, and shared resource cleanup with offboarding.

Does Aquera require scripting or manual tickets? +

No. Records from your systems of record are correlated, transformed, and synchronized into your directories automatically. Configuration is generated, then reviewed and refined, rather than coded by hand.

How do I see a demo of Aquera Identity Sourcing? +

Contact your Aquera representative or email sales@aquera.com, or visit aquera.com, to see Identity Sourcing live, from your systems of record to Day-1-ready, correctly correlated directory accounts.